Description
A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
Published: 2026-09-18
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized file ownership and permission changes
Action: Immediate Patch
AI Analysis

Impact

Cockpit‑files implements privileged operations such as changing file ownership and permissions. A timing issue—a symlink race condition—allows an attacker who has local access to the system to manipulate directory entries and win the race. By doing so, the attacker can redirect these privileged operations to arbitrary target files, leading to unauthorized ownership or permission changes. This results in compromise of system integrity and potentially availability, since critical system or application files could be altered or services rendered unusable.

Affected Systems

The vulnerability affects the cockpit-files component on Red Hat Enterprise Linux 9 and Red Hat Enterprise Linux 10 systems. No specific version information is provided in the advisory; therefore all installations of cockpit‑files on these platforms are potentially exploitable until patched.

Risk and Exploitability

The CVSS score of 6 indicates medium severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Because the attack requires local privilege and races within the cockpit-files process, an attacker must already have a user account on the target machine. If they can exploit the race, they can modify arbitrary file ownership or permissions, potentially taking control of system resources or disrupting service. The lack of a publicly disclosed exploit and the local nature of the threat suggest a moderate risk pending the deployment of a fix.

Generated by OpenCVE AI on September 19, 2026 at 10:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Red Hat security updates for the cockpit-files package to eliminate the race condition.
  • Restrict and review the ownership and permission settings of critical system files and configuration directories managed by cockpit, ensuring they are protected from unintended modification.
  • Enable SELinux or AppArmor policies that limit cockpit’s ability to perform privileged file ownership and permission changes, providing an additional security layer.

Generated by OpenCVE AI on September 19, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in cockpit-files. This vulnerability allows a local attacker to exploit a timing issue, known as a symlink race condition, during privileged file operations such as changing file ownership or permissions. By manipulating directory entries and winning this race, the attacker can redirect these operations to unintended files. This could lead to unauthorized changes in file ownership and permissions on arbitrary files, potentially compromising system integrity and availability by altering system or application states or rendering services unusable.
Title Cockpit-files: cockpit-files: arbitrary file ownership and permission modification via symlink race condition
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-363
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-22T19:26:26.445Z

Reserved: 2026-09-14T21:59:00.235Z

Link: CVE-2026-91203

cve-icon Vulnrichment

Updated: 2026-09-21T18:34:11.531Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T20:17:29.397

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-91203

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-18T16:34:00Z

Links: CVE-2026-91203 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T19:24:52Z

Weaknesses
  • CWE-363

    Race Condition Enabling Link Following